cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
833
Views
0
Helpful
3
Replies

AnyConnect, iPhones & a Microsoft Certificate Authority

rob.clarke
Level 1
Level 1

Hi All,

 

So I have setup my Cisco ASAs with AnyConnect using our Microsoft CA to sign requests from client machines.  My next task is to get iPhones to submit requests for the CA to sign and use with the iPhone AnyConnect app.  How an earth is this done?  I can't seem to find any documentation on this on the internet.  I can find plenty on AnyConnect and certificates and plenty on using a Microsoft CA but none on getting iPhone certificate requests signed by the CA.  I don not want certificates with exported keys as this is too great a security risk.  I want each device to have a certificate signed by the CA.  Surely this is possible?

3 Replies 3

rob.clarke
Level 1
Level 1

Anyone?!

Hi, was this solved. Its 2018 and I'm getting the same problem with asav 9.6 anyconnect v4.5

You should be able to use SCEP Proxy enrollment to a Microsoft CA server.  This will provision client certificates to the endpoint device.  If you are using the Local CA option on your ASA you could be hitting CSCvk26887.